freenode

← freenode

tarpit

Security & Cryptography desk

Security & Cryptography3h ago

Windows kubelet NTLM coercion via subPath UNC symlinks

CVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.

Security & Cryptography11h ago

Tomcat WebSocket security constraints can be bypassed

CVE-2026-76183 lets attackers sidestep authentication rules on WebSocket endpoints across long-supported Tomcat lines.

Security & Cryptography12h ago

xdg-dbus-proxy 0.1.9 closes Flatpak sandbox escape

CVE-2026-94422 let apps bypass D-Bus message filters and run code outside the sandbox.

Security & Cryptography34h ago

Critical Expat UTF-16 fix, Octavia RCE, and glibc loader flaws posted same week

oss-security carried a high-severity libexpat release, an OpenStack Amphora root RCE path, and two glibc dynamic-loader issues affecting AT_SECURE programs.

Security & Cryptography2d ago

HAWK exits and McEliece parameters buckle under fresh attacks

An AI-assisted lattice reduction forces HAWK out of the NIST signature round while quasipolynomial results leave Classic McEliece's proposed sizes without defenders.

Security & Cryptography7d ago

KVM/arm64 nested virt flaw allows guest escape to host

CVE-2026-89775 leaves a freed host page writable to the guest when nested virtualization is enabled, enabling cloud breakout and local root on some setups.

Security & Cryptography7d ago

Unbound 1.26.1 patches critical DNSKEY RCE and eight other flaws

NLnet Labs ships a security release fixing a heap overflow that can yield remote code execution, plus high-severity DNSSEC and CNAME issues.

Security & Cryptography7d ago

ISC patches 14 BIND 9 flaws, including remote crashes and DoS

Fixes span use-after-free bugs, DNSSEC validation errors, amplification paths, and unauthenticated crashes across recursive and authoritative roles.

Security & Cryptography8d ago

ZooKeeper ACL bypass lets anyone delete empty znodes

CVE-2026-79993 skips auth and permission checks on the internal deleteContainer opcode in 3.8 and 3.9 releases.

Security & Cryptography8d ago

ZooKeeper critical bug leaks ACL-restricted paths on reconnect

CVE-2026-59739 is an incomplete fix for an earlier watch ACL flaw and is patched in 3.8.7 and 3.9.6.

Security & Cryptography9d ago

CPython tarfile filters allow escape via hard link to symlink

CVE-2026-82049 lets crafted archives alter or disclose files outside the extraction directory on CPython 3.13 and earlier.

Security & Cryptography9d ago

Incomplete Emacs CVE-2024-53920 fix still allows code execution

Untrusted files opened in modes other than Emacs Lisp can still trigger arbitrary code via flymake.

Security & Cryptography10d ago

Canonical-signed GRUB 2.14 bypasses Secure Boot lockdown via serial MMIO

A local attacker who controls boot configuration can clear GRUB's file-verifier list and load unsigned modules while lockdown still reports enabled.

Security & Cryptography13d ago

Critical WebGL bug lets Chrome run code outside sandbox

CVE-2026-87464 is a use-after-free fixed in Chrome 153.0.8010.36; unpatched Chromium builds, including Debian’s, remain exposed.

Security & Cryptography13d ago

Camel K critical flaw lets tenants run code as the operator

CVE-2026-80351 turns tenant-controlled Maven repositories into arbitrary code execution inside the Camel K operator pod.

Security & Cryptography15d ago

Tor 0.4.9.12 patches high-severity UAFs and drops TAP keys

The security release fixes multiple memory-safety flaws and requires relays to upgrade before authorities reject legacy descriptors.

Security & Cryptography15d ago

Xen Tapdisk flaws let guests run code as root in dom0

Two out-of-bounds bugs in the userspace block backend give a malicious VM a direct path to host compromise.

Security & Cryptography18d ago

util-linux 2.42.3 fixes mount races and nsenter leaks

Four new CVEs cover failed-helper hooks, source-path TOCTOU, subdir symlink escape, and missing O_CLOEXEC; wall gets another hostname sanitization fix.

Security & Cryptography18d ago

libxml2 2.15.4 patches eight XML parsing memory flaws

The release closes out-of-bounds reads, integer overflows, and buffer overflows across regexp, dictionary, URI, XPointer, and I/O paths.

Security & Cryptography20d ago

OpenStack Glance SSRF flaws expose internal URLs and image data

Three related bugs let authenticated users reach cloud metadata and turn blind SSRF into full-read exfiltration via web-download and HTTP image APIs.

Security & Cryptography20d ago

Linux XFS flaw lets local users overwrite files for root

CVE-2026-80530 mishandles reflink flags during range exchange, letting unprivileged attackers corrupt shared file data and escalate privileges.

Security & Cryptography22d ago

FreeRDP 3.31.0 plugs five server bugs, pre-auth RCE chain

GNOME Remote Desktop and KDE krdp embeds are in scope when an administrator has enabled the service; client-only FreeRDP is not.

Security & Cryptography26d ago

Four U-Boot filesystem overflows risk pre-boot code execution

Integer overflows in ZFS, SquashFS, EXT4, and a shell move command can under-allocate heap buffers through U-Boot 2026.01-rc4.

Security & Cryptography26d ago

Vault Secrets Operator leaks privileged token to tenants

CVE-2026-8715 in versions 1.3.0–1.4.1 lets a namespaced user force the operator to exfiltrate its ServiceAccount token, a short hop from cluster-admin.

Security & Cryptography28d ago

Vim patches out-of-bounds write in bundled libvterm resize handling

Before 9.2.1013, huge terminal resize requests updated state but not clamped screen storage, so later output could write past the buffer.

Security & Cryptography29d ago

Tomcat rewrite [N] flag bug can bypass access controls

An off-by-one error in Apache Tomcat’s RewriteValve restarts rule processing at the wrong point, undermining access checks that depend on rewrite order.

Security & Cryptography29d ago

Tomcat security constraint bypass fixed as CVE-2026-65182

Path ordering could let requests slip past more restrictive access rules on shorter prefixes.

Security & Cryptography29d ago

OpenRGB root daemon allows trivial remote compromise

Flaws in the RGB control suite’s custom network protocol can fully take over systems when the server runs with default privileges.

Security & Cryptography33d ago

Classic McEliece team: new attack still slower than known methods

Preliminary review of eprint 2026/1630 finds the claimed quasipolynomial approach above designed cost for every parameter set.

Security & Cryptography33d ago

Emacs TRAMP zero-click flaw runs local shell commands

Crafted remote-style file names can execute arbitrary local commands during connection setup, with no successful remote login required.

Security & Cryptography34d ago

Ceph auth flaws force keyring rotation across OpenStack

Four CephX CVEs fixed in Ceph 19.2.6 and 20.2.4 require coordinated client upgrades before operators can safely rotate credentials used by Nova, Cinder, Glance, and Manila.

Security & Cryptography35d ago

Ceph patches CephX auth bypass and Monitor key-store leak

Tentacle 20.2.4 and Squid 19.2.6 fix a high-severity AES-CBC flaw in CephX and an authorization bug that could expose LUKS passphrases and cephadm SSH keys.

Security & Cryptography38d ago

OpenZFS on Linux full-disclosed for zpool and userns escapes

Researcher Erica Windisch publicized flaws she says let unprivileged users manipulate pools and break out of user namespaces, after notifying CERT.

Security & Cryptography42d ago

Apache Airflow 3.3.1 patches three DAG-author RCE bugs in the scheduler and API server

Three important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.

Security & Cryptography43d ago

Flatpak 1.18.1 plugs sandbox escapes and local root escalations

The stable update closes symlink and path-traversal flaws that broke app isolation, with CVE IDs still pending.

Security & Cryptography43d ago

OpenStack Designate bugs allow cross-tenant DNS zone collisions

Two flaws in multi-pool setups let tenants overlap other tenants' zones, enabling hijacks and a deterministic mDNS denial of service.

Security & Cryptography48d ago

Zapscape: KVM/x86 use-after-free lets guests escape to host

CVE-2026-64561 corrupts host shadow pages from untrusted guests when nested virtualization is exposed, especially on multi-tenant clouds.

Security & Cryptography48d ago

PowerDNS patches high-severity DNS packet resource exhaustion bug

CVE-2026-52682 lets a crafted query drive up memory and CPU use across Authoritative Server, Recursor, and dnsdist.

Security & Cryptography48d ago

Linux SCTP bug lets local users hit root and escape containers

A use-after-free in Dynamic Address Reconfiguration, CVE-2026-64564, has been fixed after more than a decade in the tree.

Security & Cryptography49d ago

Bouncy Castle Java 1.85 closes 32 CVEs in core crypto paths

The July release patches signature, AEAD, keystore, and certificate-validation flaws in a library embedded across countless JVM applications.

Security & Cryptography50d ago

X.Org patches libXfont2 font client flaws that can escalate privileges

Version 2.0.9 closes two heap memory bugs reachable from a malicious font server, one an incomplete fix from 2014.

Security & Cryptography50d ago

AI cryptanalysis forces HAWK out and hardens the SSH ML-DSA fight

An Anthropic lattice break that halved HAWK’s dimension, and an IETF call for ML-DSA drafts that immediately invoked machine-assisted attacks, have turned AI from a future worry into a live input on which post-quantum algorithms survive standardization.

Security & Cryptography50d ago

Django patches high-severity spatial lookup file-write flaw

Staff users could trigger disk writes or network requests via GDAL rasters in admin filters; four CVEs land in 5.2.17 and 6.0.8.

Security & Cryptography51d ago

Apache NiFi auth flaw let read-only users override parameter checks

CVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.

Security & Cryptography51d ago

NIST leans toward seed-only keys for HQC in draft FIPS 207

The agency plans a single private-key format for the upcoming HQC-KEM standard, departing from the dual formats allowed in ML-KEM.

Security & Cryptography53d ago

Lean 4 kernel bug lets metaprograms forge proofs of False

A nested inductive projection flaw accepted axiom-free proofs of 0 = 1 until a late July nightly fix.

Security & Cryptography54d ago

GNOME cuts vuln embargo to 30 days, stops AI-ban forwards

Longtime security coordinator Michael Catanzaro will step down in November and is seeking a successor.

Security & Cryptography55d ago

PHP security releases fix SQL injection and out-of-bounds write

Four branches ship fixes for PostgreSQL injection, Phar crashes, libgd, and a BCMath flaw limited to newer lines.

Security & Cryptography55d ago

Researcher discloses 33 flaws in stagnant cJSON library

Memory-safety and logic bugs remain unfixed in a widely vendored C JSON parser after years of stalled maintenance.

Security & Cryptography55d ago

Apache Traffic Server patches 38 flaws, some CVSS 10

Versions 9.2.15 and 10.1.4 close ACL bypasses, header smuggling paths, and dozens of other issues across 9.x and 10.x.

Security & Cryptography57d ago

Xen ships batch of fixes for guest escapes spanning grant tables, pygrub, and more

Six advisories close privilege-escalation and crash bugs across years of Xen releases, several reachable from untrusted guests.

Security & Cryptography58d ago

Resolver stacks buckle together under DNSSEC and transport CVEs

Same-day HIGH batches from Unbound, BIND, and PowerDNS show wildcard label logic and new encrypted paths failing in parallel across the software that is supposed to enforce DNS integrity.

Security & Cryptography62d ago

OpenStack Ironic Python Agent allows root command execution via NTP config

Unsanitized ntp_server values let project managers run arbitrary commands during ramdisk startup.

Security & Cryptography62d ago

Knot Resolver 6.3.0 DoQ overflow allows unauthenticated RCE

A single DNS-over-QUIC connection could overflow a heap buffer; the flaw is fixed in 6.4.1.

Security & Cryptography63d ago

IETF TLS list: structural CoI question over Security AD meets moderation warning

A challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.

Security & Cryptography63d ago

Linux UDP corking bugs yield local root on kernels since 6.1

Two heap out-of-bounds writes in fragment-boundary handling are exploitable for privilege escalation, and public exploits are out.

Security & Cryptography63d ago

Linux XFS privilege escalation, BIND and Unbound DNS flaws, and Exim local bugs land together

A kernel race, two major resolver security releases, and an Exim privilege fix were disclosed the same day.

Security & Cryptography63d ago

TLS chairs refuse to release the weighting behind a contested ML-KEM consensus call

After citing a 7/10 figure among pre-existing participants to advance pure ML-KEM, the chairs told the European Commission's PQC lead they would not disclose numbers, weights, or methods.

Security & Cryptography64d ago

Moderated over a footnote: Bernstein, pure ML-KEM, and the IETF's closed door

While the TLS working group pushed pure ML-KEM through last call, chairs repeatedly silenced the draft's most rigorous critic over a copyright protest footnote, as signals-intelligence participation went largely unexamined.

Security & Cryptography64d ago

TLS chairs call rough consensus to advance pure ML-KEM over sustained objection

Across draft-ietf-tls-mlkem-05, -07, and -08 the working group split over whether an RFC for standalone post-quantum key establishment was necessary plumbing or a dangerous signal. On 19 July 2026 the chairs found rough consensus to advance it anyway.

Security & Cryptography64d ago

libssh 0.12.1 and 0.11.5 fix stack overflow and nine other flaws

Security releases address an SFTP server buffer overflow, GSSAPI and ProxyCommand leaks, an AES-GCM integrity downgrade, and multiple denial-of-service bugs.

Security & Cryptography64d ago

snapd 2.76.1 patches LPE and two sandbox flaws

Qualys found a capabilities misconfiguration in snap-confine that yields local root, fixed alongside AppArmor and seccomp issues in Ubuntu packages from 16.04 onward.